What makes a password strong
Length matters most. Each extra character multiplies the number of possible passwords, so a 16-character random password is vastly harder to guess than an 8-character one. Randomness matters too: passwords built from words, dates or keyboard patterns are far easier to crack than their length suggests.
How this generator works
It uses your browser's cryptographically secure random number generator (crypto.getRandomValues) with rejection sampling to avoid bias, then guarantees at least one character from every set you select. The entropy estimate is length × log₂(character pool size), which assumes every character is chosen uniformly.
Good practice
- Use a unique password for every account and store them in a password manager.
- Turn on two-factor authentication where available.
- Aim for 16 or more characters for important accounts.